HIPAA Healthcare Provider Obligations and Covered Entities 2 — Questions and Answers
Question 1: A small solo-practice physician transmits claims electronically to Medicare. Under HIPAA, this physician is classified as:
- A business associate
- A covered entity (Correct answer)
- A hybrid entity
- An exempt provider
Correct answer: A covered entity
Any healthcare provider that transmits health information electronically in connection with HIPAA-covered transactions is a covered entity.
Question 2: Which of the following healthcare providers is NOT required to comply with HIPAA because they do not conduct covered electronic transactions?
- A hospital billing Medicare electronically
- A cash-only psychiatrist who never files insurance claims (Correct answer)
- A pharmacy that processes electronic prescriptions
- A group practice submitting electronic remittance advice
Correct answer: A cash-only psychiatrist who never files insurance claims
A provider that conducts no HIPAA-covered electronic transactions is not a covered entity and has no HIPAA compliance obligation.
Question 3: Under the HIPAA Privacy Rule, a covered entity must provide patients with a Notice of Privacy Practices (NPP) at what point?
- Only upon patient request
- No later than the date of first service delivery (Correct answer)
- Within 30 days of first service
- Annually, regardless of service dates
Correct answer: No later than the date of first service delivery
Covered entities must provide the NPP no later than the date of first service delivery to a patient.
Question 4: A hospital outsources its medical transcription to a company that will create and store PHI. What agreement must the hospital obtain before sharing PHI with this company?
- A memorandum of understanding
- A business associate agreement (BAA) (Correct answer)
- A HIPAA compliance certification
- A confidentiality waiver
Correct answer: A business associate agreement (BAA)
Covered entities must execute a Business Associate Agreement with any vendor that creates, receives, maintains, or transmits PHI on their behalf.
Question 5: Which entity type may voluntarily choose to be treated as a covered entity under HIPAA even if not strictly required?
- A business associate
- A hybrid entity
- A non-covered provider (Correct answer)
- A workforce member
Correct answer: A non-covered provider
A non-covered provider may voluntarily comply with HIPAA, often to facilitate electronic transactions with covered entities.
Question 6: A health plan that is self-administered and has fewer than how many participants is exempt from the HIPAA Privacy Rule?
- 25
- 50 (Correct answer)
- 75
- 100
Correct answer: 50
Self-administered health plans with fewer than 50 participants are exempt from the HIPAA Privacy Rule.
Question 7: When a covered entity undergoes a merger with another covered entity, what happens to their HIPAA obligations regarding existing BAAs?
- All BAAs are automatically voided and must be renegotiated
- The surviving entity assumes responsibility for existing BAAs (Correct answer)
- HHS must be notified and re-certify all BAAs
- BAAs expire 90 days after the merger date
Correct answer: The surviving entity assumes responsibility for existing BAAs
The surviving entity in a merger assumes the HIPAA obligations, including existing Business Associate Agreements, of both predecessor entities.
A small solo-practice physician transmits claims electronically to Medicare.
Under HIPAA, this physician is classified as: